The core of the issue seems to be this bit of code. It says that if visitor is accessing the statistics project on the production server — exactly what someone querying Medicare data would be doing — then the site should send them to the guest endpoint, which requires no credentials. That's not hacking, it's not unauthorised, it's exactly what the Medicare site was set up to do.